Two-Factor Authentication¶
Add a second step to signing in, on top of your password, using an authenticator app. Two-factor authentication is optional and is turned on per account from User Settings → Security.
Overview¶
Two-factor authentication protects your account even if your password is compromised. Once it is on:
- You need a 6-digit code from an authenticator app every time you sign in — with your email and password, or with a Google account linked to that email
- You are given a set of one-time recovery codes to use if you ever lose access to your authenticator app
Set per user
Two-factor authentication is enabled per account, not per organisation or team. There is currently no way for an admin to require it across an organisation — each person enables it on their own account.
Turning It On¶
- Open User Settings and select the Security tab
- Click Enable two-factor authentication
- Enter your password to confirm, then click Continue
- Scan the QR code with your authenticator app — or copy the Secret and enter it by hand
- Enter the 6-digit code your app generates and click Verify and enable
Compatible apps
Any standard TOTP authenticator works, including Google Authenticator, 1Password, Apple Passwords, and Authy.
Recovery Codes¶
As soon as setup is confirmed you are shown 10 recovery codes, each in the format XXXX-XXXX-XXXX.
Shown once only
Recovery codes are displayed once, immediately after setup or a regenerate. Copy or download them before continuing — they cannot be viewed again afterwards.
Each code works a single time, standing in for your authenticator app if you lose your phone or cannot generate a code.
Signing In¶
With two-factor authentication on, a correct password — or a sign-in through a linked Google account — leads to a Two-factor authentication step rather than straight into the platform:
- Enter the 6-digit code from your authenticator app and click Verify
- If you do not have your app to hand, click Use recovery code and enter one of your saved codes
Running low
Signing in with a recovery code when you have two or fewer left prompts you to generate a fresh batch.
Managing It¶
From User Settings → Security, once two-factor authentication is enabled:
| Action | What you need | Effect |
|---|---|---|
| Regenerate recovery codes | Password and a current authenticator code | Invalidates your old codes and issues 10 new ones |
| Disable | Password and a current authenticator code, or a recovery code | Turns two-factor authentication off entirely |
Locked out
If you can supply neither a current authenticator code nor a recovery code, you cannot disable two-factor authentication yourself. Contact support.
Account Lockout¶
To prevent code guessing, five incorrect attempts in a row lock further attempts on the account for 15 minutes. This applies whether the codes were entered while signing in, disabling, or regenerating.
Related Topics¶
- User Settings — Account information, teams, billing, and API access
- Organisation Settings — Organisation membership, team credit limits, and billing